Exampractice

PT0-003 Tester Practice Questions

The free PT0-003: CompTIA PenTest+ questions that deal with tester, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.

Question #1

A penetration tester needs to evaluate the order in which the next systems will be selected for testing. Given the following output: Hostname | IP address | CVSS 2.0 | EPSS hrdatabase | 192.168.20.55 | 9.9 | 0.50 financesite | 192.168.15.99 | 8.0 | 0.01 legaldatabase | 192.168.10.2 | 8.2 | 0.60 fileserver | 192.168.125.7 | 7.6 | 0.90 Which of the following targets should the tester select next?

Question #2

As part of a security audit, a penetration tester finds an internal application that accepts unexpected user inputs, leading to the execution of arbitrary commands. Which of the following techniques would the penetration tester most likely use to access the sensitive data?

Question #3

A penetration tester discovers evidence of an advanced persistent threat on the network that is being tested. Which of the following should the tester do next?

Question #5

A penetration tester would like to leverage a CSRF vulnerability to gather sensitive details from an application's end users. Which of the following tools should the tester use for this task?

Question #6

You are a penetration tester reviewing a client's website through a web browser. INSTRUCTIONS Review all components of the website through the browser to determine if vulnerabilities are present. Remediate ONLY the highest vulnerability from either the certificate, source, or cookies. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Match each item to its target.

    Question #7

    A tester is performing an external phishing assessment on the top executives at a company. Two-factor authentication is enabled on the executives' accounts that are in the scope of work. Which of the following should the tester do to get access to these accounts?

    Question #8

    During a security assessment, a penetration tester needs to exploit a vulnerability in a wireless network's authentication mechanism to gain unauthorized access to the network. Which of the following attacks would the tester most likely perform to gain access?

    Question #9

    A penetration tester gains access to a domain server and wants to enumerate the systems within the domain. Which of the following tools would provide the best oversight of domains?

    Question #10

    During an engagement, a penetration tester found some weaknesses that were common across the customer's entire environment. The weaknesses included the following: • Weaker password settings than the company standard • Systems without the company's endpoint security software installed • Operating systems that were not updated by the patch management system Which of the following recommendations should the penetration tester provide to address the root issue?

    Continue with PT0-003: CompTIA PenTest+ Exam

    Unlock the full question bank

    You have read the first 10 questions. A subscription opens every question in PT0-003: CompTIA PenTest+ Exam, the full timed practice test, and your progress and weak-topic reporting.

    • Single exam

      $19.99for 30 days

      Full question bank and practice test for one exam, for 30 days.

    • Single exam

      $49.99for 1 year

      One exam for a full year. Nothing renews and nothing to cancel.

    • Full access

      $39.99/mo

      Every exam in the catalogue, month to month.

    • Full access

      $199.99/yr

      Every exam in the catalogue for a year.

    Already subscribed? Sign in to pick up where you left off.

    All PT0-003: CompTIA PenTest+ practice questions →